Hackers abused Claude to extract secrets from 1.8M Android apps

by · BleepingComputer

Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes.

The AI company says that between December 2025 and August 2026, it recorded various forms of artificial intelligence misuse, including for cyber and influence operations,  surveillance, scams, development of biological and conventional weapons, and model distillation.

Over the eight-month period, Anthropic disrupted several activities linked to the ShinyHunters collective, infamous for massive data theft attacks that typically begin with social engineering and account compromise.

An alleged French-speaking member of the group that used the handle ‘frkoo’ distributed a credential-harvesting pipeline across ten AWS EC2 workers that downloaded from multiple stores and then scanned for secrets in 1.8 million Android APKs.

“This pipeline mass-downloaded 1.8 million distinct Android APKs from multiple app-store sources, decompiled them, and scanned for hardcoded secrets with TruffleHog,” Anthropic explains.

“Verified findings were routed in real time to a Telegram group organized into over 100 source types.”

The same actor used a separate automated process to collect GitHub organization email addresses and used them to obtain GitHub Personal Access Tokens (PATs).

The two pipelines provided initial-access credentials that 'frkoo' used "for the bulk of the confirmed breaches" associated with the hacker.

Anthropic says that 'frkoo' also set up a carding shop at policenationale[.]cc that impersonated the French national police to sell stolen payment-card records, full cardholder information, and an interactive map of victim addresses.

Suspected ShinyHunters members also stole AI API keys and used them for breaching other organizations or for reconnaissance activity.

In one case, they breached a software-as-a-service provider and stole data belonging to around 200 downstream customers.

Fast-paced attacks

With the help of Claude AI, it took a suspected ShinyHunters threat actor about 34 hours to extract authentication data and get more than 2,100 sets of Azure AD authentication tokens linked to over 40 separate corporate Microsoft tenants. According to Anthropic, "AI agents performed nearly all of the work."

Additional harmful activity involving Claude and attributed to ShinyHunters affiliates includes breaching a technology provider and stealing 1TB of data, compromising an airline, and accessing systems of an energy company.

ShinyHunters moved quickly after obtaining initial access. In the case of an enterprise software firm, the hackers went to bulk data theft in just a few hours.

In another instance, the AI company says that the attacker moved from a single stolen developer token to full administrative control in less than three hours.

Russian and Chinese hackers

Anthropic’s report also highlights activity attributed to the Russian espionage group “Midnight Blizzard,” which used Claude to automate malware development, research, infrastructure acquisition, phishing, persistence, command-and-control (C2) operations, and data exfiltration.

The threat actor also set up a feedback loop that rebuilt malware whenever security products detected it.

Anthropic observed Midnight Blizzard targeting over 20 government, defense, diplomatic, intelligence, and foreign-policy entities.

The campaigns included device-code phishing, ClickFix attacks, DNS hijacking through compromised hotel Wi-Fi providers, WhatsApp account takeovers, cloud-email theft, and Windows, Android, and iOS malware, with Claude being used throughout all attack stages.

Midnight Blizzard automated its operations through AI-driven workflows built around Claude Code skills, with the human operator primarily modifying those skills when they needed refinement.

Anthropic also describes an espionage operation attributed to a Chinese-speaking group tracked as GTG-10007, where Claude was used "as the engineering and orchestration layer of a coordinated offensive program involving a variety of tasks," such as:

  • intrusion attempts against production systems
  • reconnaissance of foreign-government networks across the Middle East, Europe, and Southeast Asia
  • a standing vulnerability-research and exploit development effort against major endpoint-security products
  • malware development
  • building an intelligence-collection platform

The GTG-10007 espionage group operated autonomous vulnerability-research workflows while the human operators were away, which uncovered multiple previously unknown vulnerabilities in a major security product.

Additionally, the automated effort also delivered "working exploits for several families of network and security appliances." The actor then leveraged the exploit code against several government organizations around the globe.

The group's operations targeted around 50 organizations across government, education, retail, energy, technology, healthcare, finance, and manufacturing, with confirmed compromises at an education-technology company, a retailer, and a Southeast Asian government agency.

The AI company notes that it disrupted the actors’ use of Claude for harmful activities and banned the threat actors' account.

Furthermore, Anthropic adjusted its guardrails based on the observed malicious use, added measures to detect future misuse faster, and contacted the authorities, industry partners, and victims.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat